THREAT OPS › Threat News › [GHSA] GHSA-pf96-p4fj-6566 (medium) — HTTPX2: Conflicting Content-Length and Transfer-Encoding headers can be auto-generated
[GHSA] GHSA-pf96-p4fj-6566 (medium) — HTTPX2: Conflicting Content-Length and Transfer-Encoding headers can be auto-generated
GHSA-pf96-p4fj-6566 Severity: medium CVE: CVE-2026-84380
HTTPX2: Conflicting Content-Length and Transfer-Encoding headers can be auto-generated
### Summary
HTTPX2 can automatically add a `Content-Length` header to a request that already contains a caller-supplied `Transfer-Encoding` header. The resulting HTTP/1.1 request contains both framing headers, which can create an ambiguous message bound
Indicators of compromise
- CVE-2026-84380cve
Original source: https://github.com/advisories/GHSA-pf96-p4fj-6566